§ Category
Category

SC

RA

Thirty-One Days of IPv4 Tenure Inside an ORB Network

China-nexus operational relay box networks rotate their egress IPs monthly and pick exit nodes inside the victim’s own region. Blocklists and impossible-travel rules don’t fire. Here’s where the detection actually lives, and what the first round of tuning has to fix.

·
Artificial Intelligence

The Sandbox Config Becomes the Whole Control Surface

Z.ai’s GLM-5.2 is a cheap, MIT-licensed, long-horizon coding agent anyone can self-host with no provider-side refusal, logging, or kill switch. Paired with fresh AISI research on autonomous container-sandbox escape, the lesson is blunt: the model was never your control point. Your runtime hardening is.

·
Cyber Tools

Zero Public IoCs for an Actively Exploited Exchange Zero-Day

CVE-2026-42897 is an actively exploited OWA cross-site-scripting flaw in Microsoft Exchange Server 2016, 2019, and Subscription Edition. CVSS 8.1, KEV-listed, federal remediation deadline May 29. A specially crafted email runs JavaScript in the victim’s OWA session — session token theft, mailbox read, send-as, mailbox rules — and the catch buried in Microsoft’s guidance is that a permanent patch is gated behind Period 2 ESU enrollment for everyone still on 2016 or 2019. The EEMS mitigation works, with caveats. Here’s what’s real about it.

·
AC

TPM-Only BitLocker: The Default Configuration YellowKey Fully Defeats

Chaotic Eclipse dropped two unpatched Windows zero-days on May 13, 2026. YellowKey turns an NTFS transaction log on a USB stick into a BitLocker bypass through WinRE — physical access, no recovery key, no PIN required on TPM-only boxes. GreenPlasma is the companion privilege escalation through CTFMON. No CVEs, no patches, and a researcher who has promised more for June’s Patch Tuesday.

·